I believe this vulnerability is existing for IOS apps, too. Trustlook they may only focus on Android
This isnt as much a "vulnerability" as it is a complete miss understanding of security and the technology they are using. Everything on the client side should be assumed as obtainable.